Answer five quick questions about your business and get an indicative SMB1001 tier readiness, plus exactly what to fix in each control area to reach the next tier.
Indicative only, takes about two minutes
SMB1001 is the Australian cyber security standard for small and medium businesses, maintained by Dynamic Standards International. It organises its controls into five areas, and certification at a tier means meeting that tier across all five. Your readiness is therefore set by your weakest area, so this tool scores each one and shows where you stand.
Your indicative SMB1001 tier readiness
Not yet scored
Answer the five questions to reveal your indicative SMB1001 tier readiness. Your overall tier is set by your weakest control area.
0 of 8 answered
Readiness by control area
Tap any control area to see exactly what would lift it to the next tier.
Where to focus first
Want to know where you really stand?
This is indicative. We run a full SMB1001 gap analysis against the standard, close the gaps, and build the evidence your certification depends on, then manage annual renewal.
This self-assessment is indicative only. It is not an SMB1001 assessment, and it does not grant or predict certification. It is based on one question per control area and verifies no evidence. Certification is issued through the CyberCert portal: Bronze, Silver and Gold are attested by a company director, and Platinum and Diamond require an accredited third-party assessor.
What is SMB1001?
SMB1001 is an Australian cyber security standard written specifically for small and medium businesses, maintained by Dynamic Standards International (DSI). The current version is SMB1001:2025. Where frameworks like ISO 27001 assume a dedicated security function and a budget to match, SMB1001 was built for businesses of roughly 5 to 200 staff, and it certifies in progressive tiers so a smaller business can reach a real, usable outcome without a two-year programme.
It also aligns deliberately with the ACSC Essential Eight, the UK's Cyber Essentials scheme and elements of the US CMMC, which is why it works as a stepping stone toward ISO 27001 rather than a dead end. This free tool gives you an indicative tier readiness in about two minutes, with no sign-up.
The five control areas
SMB1001 organises its controls into five coverage areas. Certification at a tier means meeting that tier's requirements across all five, which is why your readiness is set by your weakest area rather than your average.
Technology Management. Devices, software and systems kept current and securely configured, with nothing unsupported left in production.
Access Management. MFA enforcement, individual accounts, privilege separation and regular review of who can reach what.
Backup & Recovery. Backups that are automated, held beyond the reach of ransomware, and proven by actual restore tests.
Policies & Processes. Security policies, an incident response plan with named roles, and requirements for suppliers who touch your data.
Education & Training. Security awareness that builds genuine habits, with records of who was trained and when.
The SMB1001 tiers explained
There are five progressive tiers. The important distinction for planning is where independent assessment begins.
Bronze. Foundational controls: MFA, patching, backups, access controls and security awareness. Attested by a company director through the CyberCert portal. Most businesses reach it in 8 to 12 weeks, and it is a complete certification in its own right.
Silver. Builds on Bronze with additional technical and procedural controls. Still director-attested.
Gold. A materially broader control set than Silver, and still director-attested. This is the highest tier this tool indicates.
Platinum and Diamond. The audited tiers. An accredited third-party assessor verifies your controls and evidence before certification is issued, which is why no self-assessment can predict the outcome.
Why SMB1001 matters for South Australian businesses
Cyber security questions have moved into procurement. Larger clients ask suppliers to demonstrate a security posture, insurers ask at renewal, and government-adjacent work increasingly expects something more than a verbal assurance. For a business of 20 or 50 people, ISO 27001 is often disproportionate, and an Essential Eight maturity score is useful internally but harder to hand to a client as evidence. SMB1001 produces a shareable certificate and digital badge, which is a concrete answer to a procurement question.
We are ISO 27001 certified ourselves, so the evidence discipline SMB1001 asks for is how we already work rather than something we advise on from a distance.
How this self-assessment works
You answer one question per control area, choosing the option that best describes where you genuinely are today. Each answer maps to a readiness band, and your overall indicative tier is the lowest band across the five areas, mirroring how tiered certification actually works. The breakdown then shows, for each area, the specific step that would lift it to the next tier.
This is indicative only. It is based on a single question per control area and verifies no evidence, so treat it as a way to see roughly where you stand before committing to a formal gap analysis. A real gap analysis tests each control against the full standard and, crucially, tests whether your evidence would satisfy an assessor.
Frequently asked questions
SMB1001 is an Australian cyber security standard written specifically for small and medium businesses, maintained by Dynamic Standards International (DSI). The current version is SMB1001:2025. It organises its controls into five areas: technology management, access management, backup and recovery, policies and processes, and education and training. It was designed for businesses of roughly 5 to 200 staff and deliberately aligns with the ACSC Essential Eight, the UK's Cyber Essentials scheme and elements of the US CMMC.
There are five progressive tiers: Bronze, Silver, Gold, Platinum and Diamond. Bronze, Silver and Gold are attested by a company director through the CyberCert portal. Platinum and Diamond require independent third-party assessment, where an accredited assessor verifies your controls and evidence before certification is issued. Because certification at a tier means meeting that tier across all five control areas, your readiness is set by your weakest area.
No. This is a free, indicative self-assessment to show roughly where you stand and what to fix first. It asks one question per control area and does not verify any evidence. Actual certification is issued through the CyberCert portal, with Bronze, Silver and Gold attested by a company director and Platinum and Diamond independently audited. InterIntra can run a proper gap analysis against the full standard and manage the remediation and evidence.
No, and no self-assessment can. Platinum and Diamond require an accredited third-party assessor to verify your controls and evidence, so the outcome depends on that assessment rather than on your own view of your controls. This tool indicates readiness up to Gold, which is the highest director-attested tier. If you are targeting the audited tiers, the useful next step is a gap analysis that tests your evidence the way an assessor will.
Yes, the tool is completely free and there is no sign-up. You answer the five questions in your browser and your results appear instantly. Nothing is stored or sent, and we never ask for your email to show your result.
About two minutes. There are five questions, one for each SMB1001 control area, and your indicative tier readiness and per-area breakdown update as you answer.